SV-220289r395856_rule
V-220289
SRG-APP-000142-DB-000094
O121-C2-011900
CAT II
10
Disable functions, ports, protocols, and services that are not approved.
- - - - -
Change the SQLNET.ora, LISTENER.ora, and TNSNAMES.ora files to reflect the proper use of ports, protocols, and services that are approved at the site.
If changes to the Listener are made, the files associated with the Listener must be reloaded. Do that by issuing the following commands at the Unix/Linux or Windows prompt.
First - issue the command to see what the current status is
$ lsnrctl stat
Then load the new file that was corrected to reflect site-specific requirements.
$ lsnrctl reload
Then check the status again to see that the changes have taken place.
$ lsnrctl stat
Review the DBMS settings for functions, ports, protocols, and services that are not approved.
If any are found, this is a finding.
(For definitive information on Ports, Protocols and Services Management (PPSM), refer to http://www.disa.mil/Services/Network-Services/Enterprise-Connections/PPSM)
- - - - -
In the Oracle database, the communications with the database and incoming requests are performed by the Oracle Listener. The Oracle Listener listens on a specific port or ports for connections to a specific database. The Oracle Listener has configuration files located in the $ORACLE_HOME/network/admin directory. To check the ports and protocols in use, go to that directory and review the SQLNET.ora, LISTENER.ora, and the TNSNAMES.ora. If protocols or ports are in use that are not authorized, this is a finding.
V-220289
False
O121-C2-011900
Review the DBMS settings for functions, ports, protocols, and services that are not approved.
If any are found, this is a finding.
(For definitive information on Ports, Protocols and Services Management (PPSM), refer to http://www.disa.mil/Services/Network-Services/Enterprise-Connections/PPSM)
- - - - -
In the Oracle database, the communications with the database and incoming requests are performed by the Oracle Listener. The Oracle Listener listens on a specific port or ports for connections to a specific database. The Oracle Listener has configuration files located in the $ORACLE_HOME/network/admin directory. To check the ports and protocols in use, go to that directory and review the SQLNET.ora, LISTENER.ora, and the TNSNAMES.ora. If protocols or ports are in use that are not authorized, this is a finding.
M
4059